diff --git a/RemoteAssurancePolicy.html b/RemoteAssurancePolicy.html index cc07c9d..50bb4c7 100644 --- a/RemoteAssurancePolicy.html +++ b/RemoteAssurancePolicy.html @@ -103,7 +103,7 @@
  • MUST be approved by a board-appointed RAO
  • MUST be satisfied as to the identity and competency of the TTP in identification procedures, as though they were to be conducting the assurance themselves -
    iang: this clause would probably meet DRC C.9.a: "When the CA uses an external registration authority (RA), each RA is positively identified by CA personnel before being authorized to verify identities of subscribers and authorizations of individuals to represent organizational subscribers (see §A.2.v)." +
    iang: this clause would probably meet DRC C.9.a: "When the CA uses an external registration authority (RA), each RA is positively identified by CA personnel before being authorized to verify identities of subscribers and authorizations of individuals to represent organizational subscribers (see §A.2.v)."
  • SHOULD be the most senior Assurer available
  • @@ -164,8 +164,7 @@
  • leaving a Remote Assurance Form and copies of identity documents with the TTP for at least 60 days
  • sending a Remote Assurance Form and copies of identity documents to the Assurer by mutually agreed medium (eg post, web form or encrypted email) -
    -iang: this clause is similar to the requirement DRC C.9.b: "RAs provide the CA with complete documentation on each verified applicant for a certificate." What is different is that the criteria requires the TTP to send the form, not the Member.. +
    iang: this clause is similar to the requirement DRC C.9.b: "RAs provide the CA with complete documentation on each verified applicant for a certificate." What is different is that the criteria requires the TTP to send the form, not the Member..